Category: System Safety

  • System Safety Analysis: Methods, Tasks and Techniques

    System Safety Analysis: Methods, Tasks and Techniques

    In this ‘super post’, we will learn System Safety Analysis: Methods, Tasks and Techniques. I will show you thirteen lessons that explain each of the ten analysis tasks, the analysis process, and how to combine those tasks into a program!

    Follow the links to sample and buy lessons on individual tasks.

    Introduction

    Military Standard 882, or Mil-Std-882 for short, is one of the most widely used system-safety standards. As the name implies, this standard is used on US military systems, but it has found its way, sometimes in disguise, into many other programs around the world. It’s been around for a long time and is now in its fifth incarnation: 882E.

    Unfortunately, 882 has also been widely misunderstood and misapplied. This is probably not the fault of the standard and is just another facet of its popularity. The truth is that any standard can be applied blindly – no standard is a substitute for competent decision-making.

    In this series of posts, we will: provide awareness of this standard; explain how to use it; and discuss how to manage, tailor, and implement it. Links to each training session and to each section of the standard are provided in the following sections.


    Mil-Std-882E Training Sessions

    System Safety Process, full post here

    Photo by Bonneval Sebastien on Unsplash

    In this full-length (50 minutes) video, you will learn to:

    • Know the system safety process according to Mil-Std-882E;
    • List and order the eight elements;
    • Understand how they are applied;
    • Skilfully apply system safety using realistic processes; and
    • Feel more confident dealing with multiple standards.

    In the System Safety Process Course, we look at the general requirements of Mil-Std-882E. We cover the Applicability of the 882E tasks; the General requirements; the Process with eight elements; and the application of process theory to the real world.


    Design Your System Safety Analysis Program

    Photo by Christina Morillo from Pexels

    Learn how to Design a System Safety Program for any system in any application:

    Learning Objectives. At the end of this course, you will be able to:

    • Define what a risk analysis program is;
    • List the hazard analysis tasks that make up a program;
    • Select tasks to meet your needs; and
    • Design a tailored risk analysis program for any application.

    Analysis: 200-series Tasks

    Preliminary Hazard Identification, Task 201

    Identify Hazards.

    In this video, we find out how to create a Preliminary Hazard List, the first step in safety assessment. We look at three classic complementary techniques to identify hazards and their pros and cons. This includes all the content from Task 201, and also practical insights from my 25 years of experience with Mil-Std-882.

    You can buy the full video, plus lots of bonus material:


    Preliminary Hazard Analysis, Task 202

    See More Clearly.

    In this 45-minute session, The Safety Artisan looks at Preliminary Hazard Analysis, or PHA, which is Task 202 in Mil-Std-882E. We explore Task 202’s aim, description, scope, and contracting requirements. We also provide value-adding commentary and explain the issues with PHA – how to do it well and avoid the pitfalls.


    System Requirements Hazard Analysis, Task 203

    Law, Regulations, Codes of Practice, Guidance, Standards & Recognised Good Practice.

    In this 45-minute session, The Safety Artisan looks at Safety Requirements Hazard Analysis, or SRHA, which is Task 203 in the Mil-Std-882E standard. We explore Task 203’s aim, description, scope, and contracting requirements. SRHA is an important and complex task, which needs to be done on several levels to be successful. This video explains the issues and discusses how to perform SRHA well.


    Sub-system Hazard Analysis, Task 204

    Breaking it down to the constituent parts.

    In this video lesson, The Safety Artisan looks at Sub-System Hazard Analysis, or SSHA, which is Task 204 in Mil-Std-882E. We explore Task 204’s aim, description, scope, and contracting requirements. We also provide value-adding commentary and explain the issues with SSHA – how to do it well and avoid the pitfalls.


    System Hazard Analysis, Task 205

    Putting the pieces of the puzzle together.

    In this 45-minute session, The Safety Artisan looks at System Hazard Analysis, or SHA, which is Task 205 in Mil-Std-882E. We explore Task 205’s aim, description, scope, and contracting requirements. We also provide value-adding commentary, which explains SHA – how to use it to complement Sub-System Hazard Analysis (SSHA, Task 204) to get the maximum benefits for your System Safety Program.


    Operating and Support Hazard Analysis, Task 206

    Operate it, maintain it, supply it, dispose of it.

    In this full-length session, The Safety Artisan looks at Operating & Support Hazard Analysis, or O&SHA, which is Task 206 in Mil-Std-882E. We explore Task 205’s aim, description, scope, and contracting requirements. We also provide value-adding commentary, which explains O&SHA: how to use it with other tasks; how to apply it effectively on different products; and some of the pitfalls to avoid. We refer to other lessons for specific tools and techniques, such as Human Factors analysis methods.


    Health Hazard Analysis, Task 207

    Hazards to human health are many and various.

    In this full-length (55-minute) session, The Safety Artisan looks at Health Hazard Analysis, or HHA, which is Task 207 in Mil-Std-882E. We explore the aim, description, and contracting requirements of this complex Task, which covers: physical, chemical & biological hazards; Hazardous Materials (HAZMAT); ergonomics, aka Human Factors; the Operational Environment; and non/ionizing radiation. We outline how to implement Task 207 in compliance with Australian WHS. 


    Functional Hazard Analysis, Task 208

    Components where systemic failure dominates random failure.

    In this full-length (40-minute) session, The Safety Artisan looks at Functional Hazard Analysis, or FHA, which is Task 208 in Mil-Std-882E. FHA analyses software, complex electronic hardware, and human interactions. We explore the aim, description, and contracting requirements of this Task, and provide extensive commentary on it. 


    System-Of-Systems Hazard Analysis, Task 209

    Existing systems are often combined to create a new capability.

    In this full-length (38-minute) session, The Safety Artisan looks at Systems-of-Systems Hazard Analysis, or SoSHA, which is Task 209 in Mil-Std-882E. SoSHA analyses collections of systems, which are often put together to create a new capability, which is enabled by human brokering between the different systems. We explore the aim, description, and contracting requirements of this Task, and an extended example to illustrate SoSHA. (We refer to other lessons for special techniques for Human Factors analysis.)


    Environmental Hazard Analysis, Task 210

    Environmental requirements in the USA, UK, and Australia.

    This is the full, one-hour session on Environmental Hazard Analysis (EHA), which is Task 210 in Mil-Std-882E. We explore the aim, task description, and contracting requirements of this Task, but this is only half the video. We then look at environmental requirements in the USA, UK, and Australia, before examining how to apply EHA in detail under the Australian/international regime. This uses my practical experience of applying EHA. 

  • Human Factors Engineering: Principles and Methods

    Human Factors Engineering: Principles and Methods

    In this 40-minute video, ‘Human Factors Engineering: Principles and Methods’, I am very pleased to welcome Peter Benda to The Safety Artisan.

    Peter is a colleague and Human Factors specialist who has 23 years’ experience in applying Human Factors to large projects in all kinds of domains. In this session, we look at some fundamentals: what does Human Factors engineering aim to achieve? Why do it? And what sort of tools and techniques are useful?

    This is The Safety Artisan, so we also discuss some real-world examples of how erroneous human actions can contribute to accidents. (See this post for a fuller example of that.) And, of course, how the Human Factors discipline can help to prevent them.

    In ‘Introduction to Human Factors’, Peter explains these vital terms to us!

    Topics

    • Introducing Peter;
    • The Joint Optimization Of Human-Machine Systems;
    • So why do HFE?
    • Introduction to Human Factors;
    • Definitions of Human Factors;
    • The Long Arm of Human Factors; and
    • What is Human Factors Integration?

    Introduction to Human Factors: Transcript

    Introduction

    Simon:  Hello, everyone, and welcome to the Safety Artisan: Home of Safety Engineering Training. I’m Simon, and I’m your host, as always. But today we are going to be joined by a guest, a Human Factors specialist, a colleague, and a friend of mine called Peter Benda. Now, Peter started as one of us, an ordinary engineer, but unusually, perhaps for an engineer, he decided he didn’t like engineering without people in it. He liked the social aspects and the human aspects, and so he began to specialise in that area. And today, after twenty-three years in the business, and a first degree and a master’s degree in engineering with a Human Factors speciality. He’s going to join us and share his expertise with us.

    So that’s how you got into it then, Peter. For those of us who aren’t really familiar with Human Factors, how would you describe it to a beginner?

    Peter:   Well, I would say it’s The Joint Optimization Of Human-Machine Systems. So it’s really focusing on designing systems, perhaps help holistically would be a term that could be used, where we’re looking at optimizing the human element as well as the machine element. And the interaction between the two. So that’s really the key to Human Factors. And, of course, there are many dimensions from there: environmental, organisational, job factors, human and individual characteristics. All of these influence behaviour at work and health and safety. Another way to think about it is the application of scientific information concerning humans to the design of systems. Systems are for human use, which I think most systems are.

    Simon:  Indeed. Otherwise, why would humans build them?

    Peter:   That’s right. Generally speaking, sure.

    Simon:  So, given that this is a thing that people do, then. Perhaps we’re not so good at including the human unless we think about it specifically?

    Peter:   I think that’s fairly accurate. I would say that if you look across industries, and industries are perhaps better at integrating Human Factors considerations or Human Factors into the design lifecycle, that they have had to do so because of the accidents that have occurred in the past. You could probably say this about safety engineering as well, right?

    Simon:  And this is true, yes.

    Peter:   In a sense, you do it because you have to, because the implications of not doing it are quite significant. However, I would say the upshot, if you look at some of the evidence –and you see this also across software design and non-safety critical industries or systems –that taking into account human considerations early in the design process typically ends up in better system performance. You might have more usable systems, for example. Apple would be an example of a company that puts a lot of focus into human-computer interaction and optimizing the interface between humans and their technologies and ensuring that you can walk up and use it fairly easily. Now as time goes on, one can argue how out how well Apple is doing something like that, but they were certainly very well known for taking that approach.

    Simon:  And reaped the benefits accordingly and became, I think, they were the world’s number one company for a while.

    Peter:   That’s right. That’s right.

    Simon:  So, thinking about the “So why do it?” What is one of the benefits of doing Human Factors well?

    Peter:   Multiple benefits, I would say. Clearly, safety and safety-critical systems, like health and safety, Performance, system performance, Efficiency and so forth. Job satisfaction and that has repercussions that go back into, broadly speaking, that society. If you have meaningful work that has other repercussions, and that’s sort of the angle I originally came into all of this from. But, you know, you could be looking at just the safety and efficiency aspects.

    Simon:  You mentioned meaningful work: is that what attracted you to it?

    Peter:   Absolutely. Absolutely. Yes. Yes, as I said, I had a keen interest in the sociology of work and looking at work organisation. Then, for my master’s degree, I looked at lean production, which is the Toyota approach to producing vehicles. I looked at multiskilled teams and multiskilling, and job satisfaction. Then, looking at stress indicators and so forth versus mass production systems. So that’s really the angle I came into this. If you look at it, mass production lines where a person is doing the same job over and over, it’s quite repetitive and very narrow, versus the more Japanese-style lean production. There are certainly repercussions, both socially and individually, from a psychological health perspective.

    Simon:  So, you get happy workers and more contented workers –

    Peter:   – And better quality, yeah.

    Simon:  And again, you mentioned Toyota. Another giant company that’s presumably grown partly through applying these principles.

    Peter:   Well, they’re famous for quality, aren’t they? Famous for reliable, high-quality cars that go on forever. I mean, when I moved from Canada to Australia, Toyota had a very, very strong history here with the Land Cruiser, and the Hilux, and so forth.

    Simon:  All very well-known brands here. Household names.

    Peter: They are known to be bombproof and can outlast any other vehicle. And the lean production system certainly has, I would say, quite a bit of responsibility for the production of these high-quality cars.

    Simon:  So, we’ve spoken about how you got into it and “What is it?” and “Why do it?” I suppose, as we’ve said, what it is in very general terms, but I suspect a lot of people listening will want to know to define what it is, what Human Factors is, based on doing it. On how you do it. It’s a long, long time since I did my Human Factors training. Just one module in my master’s, so could you take me through what Human Factors involves these days in broad terms?

    Peter:   Sure, I actually have a few slides that might be useful –  

    Simon:  – Oh, terrific! –

    Peter:   – Maybe I should present that. So, let me see how well I can share this. And of course, sometimes the problem is I’ll make sure that – maybe screen two is the best way to share it. Can you see that OK?

    Simon:  Yeah, that’s great…

    (See the video for the full content)

    Introduction to Human Factors: Leave a Comment!

  • Sub-System Hazard Analysis with Mil-Std-882E

    Sub-System Hazard Analysis with Mil-Std-882E

    In this video lesson, I look at Sub-System Hazard Analysis with Mil-Std-882E (SSHA, which is Task 204). I teach the mechanics of the task, but not just that. I’m using my long experience with this Standard to teach a pragmatic approach to getting the work done.

    Task 204 is one of three tasks that integrate tightly in a Systems Engineering framework. (The others are System Hazard Analysis, Task 205, and System of Systems Hazard Analysis, Task 209.)

    SSHA is designed to be used where a formal Sub-System Specification (SSS) has been created. However, an SSS is not essential to perform this Task. The need for SSHA is usually driven by the complexity of the system and/or that sub-system development is contracted out.

    Together, we will explore Task 204’s aim, description, scope, and contracting requirements. There’s value-adding commentary, and I explain the issues with SSHA – how to do it well and avoid the pitfalls.

    This is the seven-minute demo, the full video is 40-minutes’ long.

    Topics: Sub-System Hazard Analysis

    • Preamble: Sub-system & System HA.
    • Task 204 Purpose:
      • Verify subsystem compliance;
      • Identify (new) hazards; and
      • Recommend necessary actions.
    • Task Description (six slides);
    • Reporting;
    • Contracting; and
    • Commentary.

    Transcript: Sub-System Hazard Analysis

    Introduction

    Hello, everyone, and welcome to the Safety Artisan, where you will find professional, pragmatic, and impartial instruction on all things system safety. I’m Simon – I’m your host for today, as always and it’s the fourth of April 22. With everything that’s going on in the world, I hope that this video finds you safe and well.

    Sub-System Hazard Analysis

    Let’s move straight on to what we’re going to be doing. We’re going to be talking today about subsystem hazard analysis and this is task 204 under the military standard 882E. Previously we’ve done 201, which was preliminary hazard identification, 202, which is preliminary hazard analysis, and 203, which is safety requirements hazard analysis. And with task 204 and task 205, which is system has analysis, we’re now moving into getting stuck into particular systems that we’re thinking about, whether they be physical systems or intangible. We’re thinking about the system under consideration and I’m really getting into that analysis.

    Topics for this Session

    So, the topics that we’re going to cover today, I’ve got a little preamble to set things in perspective. We then get into the three purposes of task 204. First, to verify compliance. Secondly, to identify new hazards. And thirdly, to recommend necessary actions. That would be recommended control measures for hazards and risks. We’ve got six slides of task description, a couple of slides on reporting, one on contracting, and then a few slides on some commentary where I put in my tuppence worth and I’ll hopefully add some value to the basic bones of the standard.

    It’s worth saying that you’ll notice that subsystem is highlighted in yellow and the reason for that is that the subsystem and system hazard analysis tasks are very, very similar. They’re identical except for certain passages and I’ve highlighted those in yellow. Normally I use a yellow highlighter to emphasize something I want to talk about. This time around, I’m using underlining for that and the yellow is showing you what these are different for subsystem analysis as opposed to system [hazard analysis]. And when you’ve watched both sessions on 204 and 205, I think you’ll see the significance of what I’ve done.

    Preamble – Sub-system & System HA

    Before we get started, we need to explain the system model that the 882 is assuming. If we look at the left-hand side of the hexagons, we’ve got our system in the center, which we’re considering. Maybe that interfaces with other systems. They work within the operating environment; hence we have the icon of the world, and the system and maybe other systems are there for a purpose. They’re performing some task; they’re doing some function and that’s indicated by the tools. We’re using the system to do something, whatever it might be.

    Then as we move to the right-hand side, the system is itself broken down into subsystems. We’ve got a couple here. We’ve got sub-systems A and B and then A further broken down into A1 and A2, for example. There’s some sort of hierarchy of subsystems that are coming together and being integrated to form the overall system. That is the overall picture that I’d like to bear in mind while we’re talking about this. The assumption in the 882, is we’re going to be looking at this subsystem hierarchy bottom upwards, largely. We’ll come on to that.

    Sub-System Hazard Analysis (T204)

    The purpose of the task, as I’ve said before, it’s threefold. We must verify subsystem compliance with requirements. Requirements to deal with risk and hazards. We must identify previously unidentified hazards that may emerge as we’re working at a lower level now. And we must recommend actions as necessary. Those are further requirements to eliminate all hazards or mitigate associated risks. We’ll keep those three things in mind and that will keep coming up.

    [Video continues…]

    End: Sub-System Hazard Analysis

    My name’s Simon Di Nucci. I’m a practicing system safety engineer, and I have been, for the last 25 years; I’ve worked in all kinds of domains: aircraft, ships, submarines, sensors, and command and control systems, and some work on rail air traffic management systems, and lots of software safety. So, I’ve done a lot of different things!

    You can find a free PDF of the System Safety Engineering Standard, Mil-Std-882E, here.

  • Master the Complete System Safety Assessment Process

    Master the Complete System Safety Assessment Process

    Master the Complete System Safety Assessment Process. Learn how to design, tailor, and execute a comprehensive system safety assessment programme — from Preliminary Hazard Identification through to Environmental Hazard Analysis.

    Mil-Std-882E Tasks 201–210 · 69 lessons · 10.5 hours of video · Self-paced online training

    Learn the process. Master the analyses. Build a defensible safety assessment.


    Can you design a complete System Safety Assessment Programme?

    System safety is more than identifying a few hazards and putting them into a spreadsheet.

    A credible safety programme needs to establish:

    • what can go wrong;
    • how and why it can happen;
    • who or what can be harmed;
    • how hazards are controlled;
    • whether safety requirements are adequate;
    • whether controls have been implemented;
    • whether residual risk is acceptable; and
    • whether the evidence supports your safety assessment.

    And different stages of the system lifecycle require different forms of analysis.

    That’s where this course comes in.

    System Safety Assessment takes you through the complete suite of Mil-Std-882E Tasks 201–210, showing you how the analyses fit together and, importantly, how to put them together into a coherent safety assessment programme.


    From Hazard Identification to a Complete Safety Assessment

    The course takes you through the complete sequence:

    System Safety Process

    Tailor the Safety Assessment Programme

    Identify Hazards

    Analyse Hazards

    Derive and Assess Safety Requirements

    Analyse Subsystems and the Complete System

    Analyse Operations, Human Health and Functions

    Analyse System-of-Systems and Environmental Hazards

    Build the Safety Assessment

    This is not a collection of disconnected hazard-analysis techniques.

    It is a system safety process.


    What You’ll Learn

    By completing this course, you will develop the knowledge and practical understanding to:

    Design a System Safety Assessment Programme

    Understand the overall Mil-Std-882E system safety process and determine which analyses are appropriate for your system.

    Tailor the Process

    Learn how to tailor your safety assessment activities to the characteristics, lifecycle, complexity and risk profile of your system.

    Identify Hazards Early

    Use Preliminary Hazard Identification to establish an initial understanding of the system’s hazard environment.

    Analyse Hazards Systematically

    Apply the appropriate hazard-analysis techniques at different levels of the system lifecycle and architecture.

    Assess Safety Requirements

    Understand how system requirements can introduce, control or fail to adequately address hazards.

    Analyse System and Subsystem Hazards

    Follow hazards through the system architecture and examine how subsystem design contributes to system-level risk.

    Analyse Operations and Support

    Consider hazards arising from operation, maintenance, logistics, servicing and other support activities.

    Assess Health Hazards

    Identify and analyse hazards that can affect personnel health.

    Analyse System Functions

    Apply Functional Hazard Analysis to understand how failures or abnormal functional behaviour can contribute to hazards.

    Analyse Systems of Systems

    Understand the additional challenges created when multiple systems interact to create a larger operational capability.

    Analyse Environmental Hazards

    Assess hazards associated with the operating environment and environmental conditions.


    The Complete Mil-Std-882E Task 201–210 Programme

    Task 201 — Preliminary Hazard Identification

    Start by identifying the hazards associated with the system, its intended use and its operating environment.

    Learn how to establish the foundation for subsequent safety analyses.


    Task 202 — Preliminary Hazard Analysis

    Move from initial hazard identification to structured analysis.

    Understand how hazards, causes, effects, controls and risk can be examined early enough to influence system design.


    Task 203 — System Requirements Hazard Analysis

    Examine system requirements from a safety perspective.

    Identify requirements that may introduce hazards, fail to control hazards adequately, or require additional safety provisions.


    Task 204 — Subsystem Hazard Analysis

    Take the analysis down into the subsystem level.

    Understand how subsystem design and implementation can contribute to hazards identified at the system level.


    Task 205 — System Hazard Analysis

    Bring the analysis back to the complete system.

    Examine interactions between components and subsystems and assess how the integrated system can produce hazardous outcomes.


    Task 206 — Operating and Support Hazard Analysis

    Safety doesn’t stop when the system is designed.

    Analyse hazards associated with:

    • operation;
    • maintenance;
    • servicing;
    • logistics;
    • support equipment;
    • personnel activities; and
    • other operating and support activities.

    Task 207 — Health Hazard Analysis

    Examine hazards that may affect personnel health.

    Consider the relationship between system design, operating conditions, human exposure and health effects.


    Task 208 — Functional Hazard Analysis

    Analyse system functions and determine how functional failures, degraded performance or abnormal behaviour can contribute to hazardous conditions.


    Task 209 — System-of-Systems Hazard Analysis

    Modern capabilities rarely operate in isolation.

    Learn how to consider hazards arising from the interactions between multiple systems that collectively deliver an operational capability.


    Task 210 — Environmental Hazard Analysis

    Consider the effects of the operating environment on system safety.

    Analyse environmental conditions that can contribute to hazards or affect the effectiveness of safety controls.


    Understand How the Analyses Fit Together

    One of the biggest challenges in system safety is knowing which analysis to perform, when to perform it, and how the results connect.

    The course therefore begins with the overall system safety process before working through the individual analyses.

    You will see how:

    Hazard Identification

    leads to

    Hazard Analysis

    which leads to

    Safety Requirements

    which lead to

    Design Controls

    which lead to

    Verification and Validation

    which ultimately contribute to

    Residual Risk Assessment and Safety Acceptance.

    The objective is not simply to complete ten Mil-Std-882E tasks.

    The objective is to create a coherent safety argument.


    Learn the Principle Behind the Task

    Mil-Std-882E provides a framework.

    But knowing the task number is not the same as knowing how to perform the analysis effectively.

    This course focuses on understanding:

    • what each analysis is intended to achieve;
    • what information you need before starting;
    • how to structure the analysis;
    • what questions the analyst needs to ask;
    • how the analysis relates to other safety activities;
    • what outputs should be produced;
    • how results should inform system design;
    • and how the individual analyses contribute to the overall safety assessment.

    The result?

    You develop a systems-thinking approach to safety assessment, rather than simply learning a collection of templates.


    Who Is This Course For?

    System Safety Engineers

    If system safety is your profession, this course provides a structured way to develop or refresh your understanding of the complete Mil-Std-882E analysis suite.


    Safety Engineers Moving Into a New Industry

    The principles of system safety are widely applicable.

    Use the course to understand how the Mil-Std-882E task structure can be applied across different types of complex and safety-critical systems.


    Systems Engineers

    Systems engineering and system safety are closely connected.

    This course helps you understand how hazards, requirements, architecture, design and verification interact.


    Engineering Managers and Technical Leads

    You don’t need to perform every analysis yourself.

    But you do need to understand what a good analysis looks like, what questions to ask, and whether the resulting safety evidence is credible.


    Defence and Aerospace Professionals

    Mil-Std-882E is widely associated with defence system safety.

    If you work on defence acquisition, development, integration, modification or sustainment programmes, this course provides a comprehensive foundation in the standard’s hazard-analysis framework.


    What Makes This Course Different?

    One Complete Programme

    Rather than taking isolated courses on individual hazard-analysis techniques, you can learn how the full Task 201–210 suite fits together.

    Practical System Safety

    The emphasis is on understanding how to perform the analyses, not simply reading the standard.

    Lifecycle Perspective

    The analyses are considered in the context of the system lifecycle and the decisions they are intended to support.

    Tailoring

    Not every system needs exactly the same safety programme.

    Learn how to tailor your assessment activities rather than applying a one-size-fits-all process.

    Safety Engineering Thinking

    Develop the ability to ask the right questions about hazards, causes, consequences, controls, requirements and evidence.


    What You Get

    Your enrolment provides access to:

    69 lessons

    A comprehensive programme covering the system safety process and Tasks 201–210.

    10.5 hours of video

    More than ten hours of structured instruction that you can work through at your own pace.

    Course transcripts

    Use transcripts to review and search the material.

    Course slides

    Downloadable supporting material for reference and revision.

    Quizzes

    Knowledge checks to reinforce your understanding.

    Free previews

    Preview lessons from each major section before enrolling. (The Safety Artisan)


    Course Structure

    Section 1

    The System Safety Process

    Understand the overall Mil-Std-882E system safety process.

    Section 2

    Tailoring Your System Safety Assessment Programme

    Determine how to structure an assessment programme appropriate to your system.

    Section 3

    Preliminary Hazard Identification — Task 201

    Identify the initial hazard set.

    Section 4

    Preliminary Hazard Analysis — Task 202

    Analyse hazards and establish the foundations for risk control.

    Section 5

    System Requirements Hazard Analysis — Task 203

    Examine requirements from a system safety perspective.

    Section 6

    Subsystem Hazard Analysis — Task 204

    Analyse subsystem-level hazards and controls.

    Section 7

    System Hazard Analysis — Task 205

    Analyse hazards at the integrated system level.

    Section 8

    Operating and Support Hazard Analysis — Task 206

    Analyse hazards associated with operation and support.

    Section 9

    Health Hazard Analysis — Task 207

    Assess hazards affecting personnel health.

    Section 10

    Functional Hazard Analysis — Task 208

    Analyse hazardous consequences of functional failures and abnormal behaviour.

    Section 11

    System-of-Systems Hazard Analysis — Task 209

    Analyse interactions between systems within a larger capability.

    Section 12

    Environmental Hazard Analysis — Task 210

    Assess hazards associated with environmental conditions.

    The current course contains all of these sections and associated lesson resources. (The Safety Artisan)


    From a List of Hazards to a Defensible Safety Assessment

    A safety assessment should answer more than:

    “What are the hazards?”

    It should help answer:

    What can go wrong?

    Why can it go wrong?

    What are the consequences?

    What controls prevent or mitigate the hazard?

    How do we know those controls are effective?

    What requirements implement the controls?

    What evidence demonstrates that the controls have been implemented?

    What risk remains?

    This is the thinking that turns hazard analysis into system safety engineering.


    Learn From More Than 30 Years of Safety-Critical Engineering

    The Safety Artisan was created to make practical system safety and safety engineering knowledge accessible to engineers and professionals.

    The training draws on more than 30 years of experience working with safety-critical systems across aerospace, defence and other complex engineering environments.

    The focus is deliberately practical:

    Understand the problem.

    Apply the engineering method.

    Produce useful safety evidence.


    Your Investment

    System Safety Assessment

    $995

    69 lessons · 10.5 hours of video · Self-paced online training

    Build the knowledge you need to design and execute a comprehensive system safety assessment programme.


    Frequently Asked Questions

    Is this course only for defence engineers?

    No.

    Although the course is based on the Mil-Std-882E framework, the underlying system safety principles and hazard-analysis techniques can be applied to many types of complex and safety-critical systems.


    Do I need to be an experienced safety engineer?

    No.

    The course is designed to provide a structured progression from the overall system safety process through the individual analyses.

    A basic understanding of systems engineering and engineering risk will be useful.


    Does the course cover all Mil-Std-882E Tasks 201–210?

    Yes.

    The current course covers the system safety process and Tasks 201 through 210, including Preliminary Hazard Identification, Preliminary Hazard Analysis, System Requirements Hazard Analysis, Subsystem Hazard Analysis, System Hazard Analysis, Operating and Support Hazard Analysis, Health Hazard Analysis, Functional Hazard Analysis, System-of-Systems Hazard Analysis and Environmental Hazard Analysis. (The Safety Artisan)


    Does the course teach me how to use a particular software tool?

    The focus is on system safety engineering methods and analysis, rather than training in a particular software package.

    The principles can therefore be applied using the tools and processes used by your organisation.


    Is this a clause-by-clause explanation of Mil-Std-882E?

    No.

    The objective is to help you understand and apply the system safety process and associated analyses, rather than simply memorising the wording of the standard.


    Can I work through the course at my own pace?

    Yes.

    The course is delivered online and is designed for self-paced learning.

    You can work through the lessons when it suits you and revisit material as required.


    How much material is included?

    The course currently contains 69 lessons and approximately 10.5 hours of video content, together with supporting transcripts, slides and quizzes. (The Safety Artisan)


    Ready to Build Your System Safety Assessment Skills?

    You don’t need another collection of disconnected hazard-analysis techniques.

    You need to understand how the analyses fit together into a system safety programme.

    System Safety Assessment gives you a structured path through the complete Mil-Std-882E Task 201–210 analysis suite.

    Learn the process.

    Master the analyses.

    Build a defensible safety assessment.

    $995

    69 lessons · 10.5 hours of video · Self-paced online training


    Don’t Just Identify Hazards.

    Learn How to Engineer Safety.

  • ISSS Credentialing Initiative: System Safety Professionals

    ISSS Credentialing Initiative: System Safety Professionals

    The ISSS Credentialing Initiative: System Safety Professionals. Where is the Next Generation of System Safety Professionals? We need a Workforce Development Program for Safety-Critical Industries.

    The International System Safety Society (ISSS) is launching a major credentialing initiative designed to strengthen and expand system safety capability across Canada and the United States.

    Developed as a three-year industry partnership and sponsorship program, the initiative will create a structured pathway for professionals working with complex and safety-critical systems. The program combines modular learning, stackable micro-credentials, and verifiable digital certifications to help organizations build a stronger and more resilient safety workforce.

    The initiative is being led by an ISSS sub-committee including Jenn Downing, ISSS Director of Education and Professional Development, and Carol-Ann Haggarty.

    Why This Initiative Matters

    Organizations operating in safety-critical environments face increasing challenges in recruiting, developing, and retaining personnel with the skills required to manage system safety throughout the lifecycle of complex systems.

    Whether in defence, aerospace, transportation, energy, healthcare technology, telecommunications, or critical infrastructure, employers require practitioners who understand:

    • Hazard identification and analysis
    • Risk assessment and acceptance
    • Safety assurance and evidence generation
    • Lifecycle safety management
    • Safety-informed decision making

    The ISSS Credentialing Initiative addresses these challenges by creating a common, industry-recognized framework for developing and validating system safety competencies.

    A Three-Year Development and Trial Program

    The initiative will be delivered through a structured three-year model.

    Year 1 – Build

    The first year focuses on developing:

    • The credentialing framework
    • Course architecture and learning pathways
    • Pilot training materials
    • Instructor guidance
    • Digital credentialing mechanisms
    • Evaluation and assessment strategies

    Year 2 – Pilot

    Pilot courses will be delivered with industry, academic, and professional partners. Feedback will be collected to evaluate:

    • Learning effectiveness
    • Practical relevance
    • User experience
    • Workforce applicability

    Year 3 – Refine and Scale

    Following the pilot phase, the program will be refined and prepared for wider deployment across Canada and the United States. The goal is to establish a sustainable and scalable credentialing model that meets long-term workforce needs.

    Creating a Workforce Pipeline

    The credentialing pathway is designed to support professional development from entry into the workforce through to advanced practice.

    The model provides a clear progression:

    Students and Early-Career Professionals → ISSS Micro-Credentials → Verified Skills → Industry Deployment → Career Progression

    This approach helps organizations identify talent, validate competencies, and accelerate workforce readiness.

    Cross-Industry Applicability

    A key strength of the program is its portability across industries.

    The credentialing model is intended to be standards-aware while remaining industry-neutral, making it applicable to sectors including:

    • Defence and aerospace
    • Space systems
    • Nuclear and energy
    • Rail and public transit
    • Automotive and autonomous systems
    • Medical technology
    • Mining and industrial operations
    • Critical infrastructure
    • Software-intensive systems
    • Manufacturing and robotics
    • Telecommunications
    • Public-sector acquisition

    By focusing on disciplined safety thinking, evidence-based assurance, and risk management principles, the framework can support organizations operating under a wide range of regulatory and operational environments.

    Benefits for Industry Partners

    Industry participation is central to the success of the initiative.

    Partner organizations can help ensure that the credentialing framework remains practical, current, and aligned with real workforce requirements. Benefits include:

    Improved Workforce Readiness

    Employees gain foundational and applied knowledge in system safety principles, reducing training gaps and improving operational effectiveness.

    A Common Professional Language

    The program promotes alignment across safety, systems engineering, software engineering, quality assurance, human factors, compliance, and program management functions.

    Reduced Onboarding Costs

    Organizations gain access to personnel with a recognised baseline of knowledge and capability, reducing the need to repeatedly teach foundational concepts internally.

    Scalable Capability Development

    The modular structure allows organizations to support workforce development at scale while maintaining consistency across teams and locations.

    Inclusive Workforce Development

    The ISSS Credentialing Initiative is built upon Universal Design for Learning (UDL) principles.

    The program seeks to expand access to system safety careers for:

    • Students
    • Early-career professionals
    • Engineers transitioning between industries
    • Practitioners returning to the workforce

    Learning will be delivered through flexible formats, including self-paced modules, micro-learning approaches, and multiple assessment methods.

    This inclusive design helps broaden participation, improve learner confidence, and strengthen the long-term safety engineering talent pipeline across North America.

    Opportunities for Sponsorship and Partnership

    ISSS is currently seeking organizations willing to support the development and trial period through one or more of the following roles:

    Sponsors

    Provide financial support for:

    • Curriculum development
    • Pilot delivery
    • Evaluation activities
    • Accessible learning design
    • Launch preparation

    Partners

    Support the initiative by:

    • Nominating pilot participants
    • Reviewing course relevance
    • Providing structured feedback
    • Validating workforce outcomes

    Champions

    Help expand awareness by connecting ISSS with:

    • Industry networks
    • Professional societies
    • Academic institutions
    • Government stakeholders
    • Potential implementation partners

    Sponsors may also receive benefits including brand recognition, pilot course access, participation in feedback activities, and discounted access during the formal rollout phase.

    The Next Step

    The ISSS Credentialing Initiative represents an opportunity to build a sustainable and scalable system safety workforce development framework for North America.

    Organizations interested in shaping the future of system safety education and professional development are invited to:

    • Become a partner
    • Sponsor the initiative
    • Nominate pilot participants
    • Contribute subject matter expertise
    • Support long-term rollout and adoption

    By working together, industry, academia, government, and professional societies can help create a stronger pipeline of qualified professionals capable of supporting the increasingly complex and safety-critical systems upon which modern society depends.

    ISSS 2026 Summit & Training (Click on Link in Image)

    Hi, I’m Simon Di Nucci. I am a practicing system safety engineer and have been for the last 30 years. I’ve worked in all kinds of domains: aircraft, ships, submarines, sensors, and command-and-control systems, rail, air traffic management systems, and lots of software safety. So, I’ve done a lot of different things!

  • Sub-System Hazard Analysis with Mil-Std-882E

    Sub-System Hazard Analysis with Mil-Std-882E

    In this video lesson, I look at Sub-System Hazard Analysis with Mil-Std-882E (SSHA, which is Task 204). I teach the mechanics of the task, but not just that. I’m using my long experience with this Standard to teach a pragmatic approach to getting the work done.

    Task 204 is one of three tasks that integrate tightly in a Systems Engineering framework. (The others are System Hazard Analysis, Task 205, and System of Systems Hazard Analysis, Task 209.)

    SSHA is designed to be used where a formal Sub-System Specification (SSS) has been created. However, an SSS is not essential to perform this Task. The need for SSHA is usually driven by the complexity of the system and/or that sub-system development is contracted out.

    Together, we will explore Task 204’s aim, description, scope, and contracting requirements. There’s value-adding commentary, and I explain the issues with SSHA – how to do it well and avoid the pitfalls.

    This is the seven-minute demo, the full video is 40-minutes’ long.

    Topics: Sub-System Hazard Analysis

    • Preamble: Sub-system & System HA.
    • Task 204 Purpose:
      • Verify subsystem compliance;
      • Identify (new) hazards; and
      • Recommend necessary actions.
    • Task Description (six slides);
    • Reporting;
    • Contracting; and
    • Commentary.

    Transcript: Sub-System Hazard Analysis

    Introduction

    Hello, everyone, and welcome to the Safety Artisan, where you will find professional, pragmatic, and impartial instruction on all things system safety. I’m Simon – I’m your host for today, as always and it’s the fourth of April 22. With everything that’s going on in the world, I hope that this video finds you safe and well.

    Sub-System Hazard Analysis

    Let’s move straight on to what we’re going to be doing. We’re going to be talking today about subsystem hazard analysis and this is task 204 under the military standard 882E. Previously we’ve done 201, which was preliminary hazard identification, 202, which is preliminary hazard analysis, and 203, which is safety requirements hazard analysis. And with task 204 and task 205, which is system has analysis, we’re now moving into getting stuck into particular systems that we’re thinking about, whether they be physical systems or intangible. We’re thinking about the system under consideration and I’m really getting into that analysis.

    Topics for this Session

    So, the topics that we’re going to cover today, I’ve got a little preamble to set things in perspective. We then get into the three purposes of task 204. First, to verify compliance. Secondly, to identify new hazards. And thirdly, to recommend necessary actions. That would be recommended control measures for hazards and risks. We’ve got six slides of task description, a couple of slides on reporting, one on contracting, and then a few slides on some commentary where I put in my tuppence worth and I’ll hopefully add some value to the basic bones of the standard.

    It’s worth saying that you’ll notice that subsystem is highlighted in yellow and the reason for that is that the subsystem and system hazard analysis tasks are very, very similar. They’re identical except for certain passages and I’ve highlighted those in yellow. Normally I use a yellow highlighter to emphasize something I want to talk about. This time around, I’m using underlining for that and the yellow is showing you what these are different for subsystem analysis as opposed to system [hazard analysis]. And when you’ve watched both sessions on 204 and 205, I think you’ll see the significance of what I’ve done.

    Preamble – Sub-system & System HA

    Before we get started, we need to explain the system model that the 882 is assuming. If we look at the left-hand side of the hexagons, we’ve got our system in the center, which we’re considering. Maybe that interfaces with other systems. They work within the operating environment; hence we have the icon of the world, and the system and maybe other systems are there for a purpose. They’re performing some task; they’re doing some function and that’s indicated by the tools. We’re using the system to do something, whatever it might be.

    Then as we move to the right-hand side, the system is itself broken down into subsystems. We’ve got a couple here. We’ve got sub-systems A and B and then A further broken down into A1 and A2, for example. There’s some sort of hierarchy of subsystems that are coming together and being integrated to form the overall system. That is the overall picture that I’d like to bear in mind while we’re talking about this. The assumption in the 882, is we’re going to be looking at this subsystem hierarchy bottom upwards, largely. We’ll come on to that.

    Sub-System Hazard Analysis (T204)

    The purpose of the task, as I’ve said before, it’s threefold. We must verify subsystem compliance with requirements. Requirements to deal with risk and hazards. We must identify previously unidentified hazards that may emerge as we’re working at a lower level now. And we must recommend actions as necessary. Those are further requirements to eliminate all hazards or mitigate associated risks. We’ll keep those three things in mind and that will keep coming up.

    [Video continues…]

    End: Sub-System Hazard Analysis

    My name’s Simon Di Nucci. I’m a practicing system safety engineer, and I have been, for the last 25 years; I’ve worked in all kinds of domains, aircraft, ships, submarines, sensors, and command and control systems, and some work on rail air traffic management systems, and lots of software safety. So, I’ve done a lot of different things!

    You can find a free pdf of the System Safety Engineering Standard, Mil-Std-882E, here.

  • System Requirements Hazard Analysis

    System Requirements Hazard Analysis

    In this 45-minute session, I’m looking at System Requirements Hazard Analysis, or SRHA, which is Task 203 in the Mil-Std-882E standard. I will explore Task 203’s aim, description, scope, and contracting requirements.  SRHA is an important and complex task, which must be done on several levels to succeed.  This video explains the issues and discusses how to perform SRHA well.

    This is the seven-minute demo video, the full version is 40 minutes’ long.

    Topics: System Requirements Hazard Analysis

    • Task 202 Purpose;
    • Task Description:
      • Determine Requirements;
      • Incorporate Requirements; and
      • Assess the compliance of the System.
    • Contracting;
    • Section 4.2 (of the standard); and
    • Commentary.

    Transcript

    Introduction

    Hello and welcome to the Safety Artisan, where you will find professional, pragmatic and impartial advice on all things system, safety and related.

    System Requirements Hazard Analysis

    Today, we’re talking about system requirements hazard analysis. And this is part of our series on Mil. Standard 882E, and this one is Task 203. And it’s a very widely used system safety engineering standard. Its influence is found in many places, not just in military procurement programs.

    Topics for this Session

    We’re looking at this task, which is very important, possibly the most important task of all, as we’ll see. I’m talking about the purpose of the task, which is word-for-word from the task description itself.

    We’re talking about in the task description, the three aims of this task, which is to determine or work out requirements, incorporate them, and then assess the compliance of the system with those requirements, because, of course, it may not be a simple read-across. We’ve got six slides on that. That’s most of the task.

    Then we’ve just got one slide on contracting, which if you’ve seen any of the others in this series, will seem very familiar. We’ve got a bit of a chat about Section 4.2 from the standard and some commentary, and the reason for that will become clear. Let’s crack on!

    System Requirements Hazard Analysis

    Task 203.1, the purpose of Task 203 is to perform and document a System Requirements Hazard Analysis or SRHA. And as we’ve already said, the purpose of this is to determine the design requirements. We’re going to focus on design rather than buying stuff off the shelf – we’ll talk about the implications of that a little bit later.

    Design requirements to eliminate or reduce hazards and risks, incorporate those requirements, into a says, into the documentation, but what it should say is incorporate risk reduction measures into the system itself and then document it.

    Finally, to assess compliance of the system with these requirements. Then it says the SRHA address addresses all life-cycle phases, so not just meant for you to think about certain phases of the program. What are the requirements through life for the system? And in all modes. Whether it’s in operation, whether it’s in maintenance or refit, whether it’s being repaired or disposed of, whatever it might be.

    Task Description #1

    The first of six slides is the task description. I’m using more than one colour because there’s some quite a lot of important points packed quite tightly together in this description.

    We’re assuming that the contractor performs and documents this SRHA. The customer needs to do a lot of work here before ever gets near a contractor. More on that later. We need to determine system design requirements to eliminate hazards or reduce associated risks.

    Two things here. By identifying applicable policies, regulations, standards, etc. More on that later. And analyzing identified hazards. So, requirements to perform the analysis as well as to simply just state ‘We want a system to do this and not to do that’. So, we need to put some requirements to say ‘Here’s what we want analyzed maybe to what degree? And why.’ is always helpful.

    Task Description #2

    Breaking those breaking those two requirements down.

    Part a. We identify applicable requirements by reviewing our military and industry standards and specs, and historical documentation of systems that are similar or with a system that we’re replacing, perhaps. It’s assumed that the US Department of Defense is the customer, the ultimate customer. So, the ultimate customer’s requirements, including whatever they’ve said about standard ways of mitigating certain common risks.

    The system performance spec, that’s your functional performance spec or whatever you want to call it. Other system design requirements and documents – a bit of a catchall there. And applicable federal, military, state, and local regulations.

    This is a US standard. It’s a federated state, much like Australia and lots of modern states, even the UK. There are variations in law across England, Wales, Scotland and Ireland. They’re not great, but they do exist.

    And in the US and Australia, those differences are greater. And it says applicable executive orders. Executive orders, they’re not law, but they are what the executive arm of the U.S. government has issued, and international agreements. There are a lot of words in there – have a look at the different statements that are in white, blue, and yellow.

    Basically, from international agreements right down to whatever requirements may be applicable, they all need to be looked at and accounted for. So, there’s a huge amount of work there for someone to do. I’ll come back to who that someone should be later.

    End: System Requirements Hazard Analysis

    You can find a free pdf of the System Safety Engineering Standard, Mil-Std-882E, here.

    Meet the Author

    Learn safety engineering with me, an industry professional with 25 years of experience, I have:

    •Worked on aircraft, ships, submarines, ATMS, trains, and software;

    •Tiny programs to some of the biggest (Eurofighter, Future Submarine);

    •In the UK and Australia, on US and European programs;

    •Taught safety to hundreds of people in the classroom, and thousands online;

    •Presented on safety topics at several international conferences.

  • Identify and Analyze Functional Hazards

    Identify and Analyze Functional Hazards

    So, how do we identify and analyze functional hazards? I’ve seen a lot of projects and programs. We’re great at doing the physical hazards, but not so good at the functional hazards.

    Introduction: Identify and Analyze Functional Hazards

    So, when I talk about physical and functional hazards, the physical stuff, I think we’re probably all very familiar with them. They’re all to do with energy and toxicity.

    Physical Hazards

    So with energy, it might be fire, it might be electric shock. Potential energy, the potential energy of someone at height, or something falling. The impact of the kinetic energy. And then of course, in terms of toxicity, we’ve got hazardous chemicals, which we have to deal with. And then we’ve got biological hazards, plus smoke and toxic gasses, often from fires. Or chemical reactions.

    So those are your physical hazards. As I said, we tend to be good at dealing with those. We’re used to dealing with that stuff. And most projects I’ve been on have been pretty good at identifying and analyzing that stuff. Not so for functional hazards.

    Functional Hazards

    I’ve been on lots of projects still today where functional hazards are just ignored completely or they’re only dealt with partially. So let’s explain what I mean about functional hazards. What we’re talking about is where a system is required to do something to perform some function. For example, cars move. They start, they move and they stop, hopefully.

    Loss of Function

    But what happens when those functions go wrong? What happens when we don’t get the function when we need it? The brakes fail on your car, for example. And so that’s a fairly obvious one. When functional hazards are looked at, it’s usually the functional failures that get attention.

    But if that is the obvious failure mode, the less obvious failure modes tend to be more dangerous and there are the two.

    Other Functional Failure Modes

    So what happens if things work when they shouldn’t? What if you’re driving along on a road or the motorway, perhaps at high speed, and your brakes slam on for no apparent reason? Perhaps there is somebody behind you. Do you have a collision or do you lose control on the road and crash?

    What if the function works, but it works incorrectly? For example, you turn the temperature down but instead, it goes up. Or you steer to the left, but instead, your vehicle goes to the right.

    What if a display shows the wrong information? If you’re in a plane, maybe you’ve got an altimeter that tells you how high you are. It would be dangerous if the altimeter told you that you were level or climbing, but you were descending towards the ground. Yeah, we’ve had lots of that kind of accident.

    So there’s an overview of what I mean by physical and functional hazards.

    The Webinar: Identify and Analyze Functional Hazards

    See the whole webinar at the Safety Engineering Academy. (You can get discounts on membership by subscribing to my free emails.)

    Course Curriculum

    1. Introduction
    2. Preliminary Hazard Identification (PHI)
    3. Functional Failure Analysis
    4. Functional Hazard Analysis (FHA)

    There are 11 lessons with two-and-a-half hours of video content, plus other resources. See the Foundations of System Safety here.

    Meet the Author

    Learn safety engineering with me, an industry professional with 25 years of experience, I have:

    •Worked on aircraft, ships, submarines, ATMS, trains, and software;

    •Tiny programs to some of the biggest (Eurofighter, Future Submarine);

    •In the UK and Australia, on US and European programs;

    •Taught safety to hundreds of people in the classroom, and thousands online;

    •Presented on safety topics at several international conferences.

  • Understanding System Safety Engineering: A Quick Guide

    Understanding System Safety Engineering: A Quick Guide

    Understanding System Safety Engineering: A Quick Guide, takes you through some key points of this complex subject.

    Introduction

    System safety engineering plays a crucial role in ensuring the safety of complex systems. In this post, we will explore the fundamental concepts of system safety engineering and its importance in the realm of systems engineering.

    System Safety Engineering Explained

    System safety engineering, as the name implies, focuses on engineering safety within a systems-engineering context. It involves deliberately integrating safety measures into the framework of complex systems.

    Read on, or watch this short video for some pointers:

    What is System Safety Engineering?

    Key Points of System Safety Engineering

    1. Consider the Whole System

    In system safety engineering, a holistic approach is essential. It’s not just about hardware and technical aspects; it includes software, operating environments, functions, user interactions, and data. This comprehensive view aligns with systems theory, ensuring a thorough safety assessment.

    2. A Systematic Process

    System safety engineering follows a systematic process. Starting with high-level requirements, it meticulously analyzes potential risks, safety obligations, and components. The V model illustrates this structured approach, emphasizing the importance of verification and validation at every stage.

    The #Systems-Engineering 'V' Model
    The Systems Engineering ‘V’ Model

    3. Emphasis on Requirements

    Unlike simple commodities like toasters, complex systems require rigorous requirement analysis. System engineers meticulously decompose the system, defining boundaries, interactions, and functionalities. These requirements undergo rigorous validation, minimizing surprises and ensuring safety from the start.

    Bowtie diagram showing five types of hazard analysis.
    Bowtie showing the Foundations of System Safety

    4. Think Safety from the Start

    A significant aspect of system safety engineering is the early integration of safety considerations. By addressing safety concerns right from the beginning, potential issues are identified and resolved cost-effectively. This proactive approach enhances the overall safety of the system.

    Setting the direction towards safety from the start
    Which way should we go?

    Summary

    In summary, system safety engineering is characterized by its systematic approach to understanding the entire system, following a structured process, and integrating concepts from systems engineering and systems theory. By focusing on comprehensive requirements and thinking about safety from the start, system safety engineering ensures the safety and reliability of complex systems.

    Meet the Author

    My name’s Simon Di Nucci. I’m a practicing system safety engineer, and I have been, for the last 25 years; I’ve worked in all kinds of domains, aircraft, ships, submarines, sensors, and command and control systems, and some work on rail air traffic management systems, and lots of software safety. So, I’ve done a lot of different things!

    Meet the Author

    If you found this helpful, there’s more depth in this article, and you can also see System Safety FAQ. There’s a low-price introductory course on the System Safety Process – on Udemy (please use this link, otherwise Udemy takes two-thirds of the revenue).

  • System Safety FAQ

    System Safety FAQ

    Introduction

    In System Safety FAQs, I will deal with the most commonly searched-for online queries.  This post is also the basis for the First in a new series of monthly webinars I’m running.  I will also be answering your questions: leave them in the comments at the bottom of this post!

    What is System Safety?

    “System Safety is the application of engineering and management principles, criteria and techniques to achieve acceptable mishap risk within the constraints of operational effectiveness and suitability, time and cost throughout all phases of the system life cycle.”

    NASA

    This definition from NASA is spot on. System Safety is fundamentally about reducing the risks of mishaps (accidents). The NASA Office of Safety and Mission Assurance website is great for practitioners!

    The #Systems-Engineering 'V' Model
    The Systems Engineering ‘V’ Model

    “The system safety concept calls for a risk management strategy based on identification, analysis of hazards and application of remedial controls using a systems-based approach”.[1] 

    Wikipedia

    This Wikipedia article reminds us that safety risk management is a subset of risk management in general.  It also brings in the concept of a ‘hazard’, which is typical for ‘system safety’ – see my free lesson on basic risk concepts for more information.

    Where Does Safety Start?

    Safety is an ‘emergent property’, that is, it comes about by pulling together many different things.  Only leaders and managers can deliver these things; it doesn’t work if you try to do it from the bottom up.

    “Safety undoubtedly starts at the top. The people leading the organization are the ones most responsible for its safety. It’s simple.”

    Avatarms.com

    I would also say that safety begins at the start of the lifecycle with requirements – see my short video about what System Safety is:

    Safe System Approach?

    “The Safe System approach adopts a holistic view of the road transport system and the interactions between people, vehicles, and the road environment. It recognises that people will always make mistakes and may have road crashes – but those crashes should not result in death or serious injury.”

    Thinkroadsafety.sa.gov.au

    This is a great view of a safe system approach, or strategy, from the world of road safety.  Road networks, their commercial and private users, neighbours, regulators, emergency services, etc., form a very complex distributed system.

    Why System Safety?

    What are the benefits?

    “A customised Safety Management System will help you create an environment where all employees are empowered to identify hazards before they become problems, so your business can stay safe without losing focus on growth, profit or innovation.”

    Worksafetyhub.com.au

    I would add that a systematic approach to safety saves time and money in the long run.

    System Safety for The 21st Century

    Traditional System Safety has its critics, most famously professors Nancy Leveson and Erik Hollnagel.  They have made various criticisms of system safety – some of which I agree with, and some I most definitely do not.

    Leveson has proposed new methods:

    • System-Theoretic Accident Model and Processes (STAMP);
    • Systems Theoretic Process Analysis (STPA); and
    • Causal Analysis using System Theory (CAST) – accident analysis.

    Hollnagel has written on a wide variety of safety topics, including cognition, organisational robustness, and resilience.  He also coined the terms “Safety I” for traditional safety approaches and “Safety II” to describe the conceptual approach that he and others have developed.

    He designed the Functional Resonance Analysis Method (FRAM). 

    “THE FRAM is a method to analyse how work activities take place either retrospectively or prospectively. This is done by analysing work activities in order to produce a model or representation of how work is done.”

    Functionalresonance.com

    I have tried FRAM, and even without any training (which is recommended), I found it tremendously powerful.  FRAM can analyse problems that conventional safety techniques just can’t get to grips with.   

    From FRAM in a Nutshell by Mohammad Tishehzan at https://etn-peter.eu/2021/02/11/fram-in-a-nutshell/
    From ‘FRAM in a Nutshell’ by Mohammad Tishehzan at etn-peter.eu

    Others have also introduced the term “Safety III”, but I’m not sure how useful these labels are.  Perhaps we are now on a trajectory of diminishing returns.

    System Safety is a Design Parameter

    To save us from all this abstract navel-gazing, let’s get back to practical matters.

    “Safety-related parameters are control system variables whose incorrect setting immediately increases the risk to the user.”

    Machinery101.com

    Concrete, specific, practical: I love it!  Let’s not forget that we do safety for a reason, and a big part of that is to control the machines that make our modern world.  This doesn’t sound very exciting, but automation has enabled huge increases in productivity, wealth, health, quality of life, lifespan and human rights.  Let’s remember that during the current hysteria about Artificial Intelligence (actually Machine Learning).

    Safety System of Work

    “a safe system of work such as safety procedures. information, supervision, instruction and training on the safe use, handling and storage of machinery, structures, substances and other work tasks. personal protective equipment as required. a system to identify hazards, assess and control risks.”

    Safework.sa.gov.au

    If we think about it, this ties in nicely with the definition of a system used in system safety, e.g.:

    “A combination, with defined boundaries, of elements that are used together in a defined operating environment to perform a given task or achieve a specific purpose. The elements may include personnel, procedures, materials, tools, equipment, facilities, services and/or software as appropriate.”

    UK Defence Standard 00-56/1

    System Safety in Engineering

    There are a number of ways that we could answer this (implicit) question.  Here’s one from the Office of The Under Secretary Of Defense For Research and Engineering:

    “System safety engineering involves planning, identifying, documenting, and mitigating hazards that contribute to mishaps involving defense systems, platforms, or personnel (military and the public). The system safety practice aids in optimizing the safety of a system.”

    Ac.cto.mil

    This definition neatly pulls together activities, hazards and accidents, those impacted and the aim of the whole thing.  Phew!

    There’s More!

    Questions and Comments?

    Please leave them below.

    Meet the Author

    My name’s Simon Di Nucci. I’m a practicing system safety engineer, and I have been, for the last 25 years; I’ve worked in all kinds of domains, aircraft, ships, submarines, sensors, and command and control systems, and some work on rail air traffic management systems, and lots of software safety. So, I’ve done a lot of different things!

    Meet the Author

    [1] Harold E. Roland; Brian Moriarty (1990). System Safety Engineering and Management. John Wiley & Sons. ISBN 0471618160.